Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALbajo ataqueransomware26 may 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware26 may 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DBVexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
CVE-2020-11108webappslinux26 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware26 may 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
gothburz/cve-2020-8617
CVE-2020-8617HIGH26 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
Exploit-DBVexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
CVE-2020-13166remotewindows25 may 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RIESGO
abrir
GitHub PoC12
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware25 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-261825 may 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque25 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware25 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
Exploit-DBVexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
CVE-2017-15889remotehardware25 may 2020
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir
GitHub PoC22
CVE-2020-2551 POC to use in Internet
CVE-2020-2551CRITICALbajo ataque24 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC87
QNAP pre-auth root RCE Exploit (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALbajo ataqueransomware24 may 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-7192CRITICALbajo ataqueransomware24 may 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque23 may 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC1
vulnerabilidad CVE-2019-0708 testing y explotacion
CVE-2019-0708CRITICALbajo ataqueransomware23 may 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC5
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS)
CVE-2020-7961CRITICALbajo ataque23 may 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Exploit-DBVexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
CVE-2020-2555CRITICALbajo ataqueremotemultiple22 may 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Metasploit300
Documalis Free PDF Editor and Scanner JPEG Stack Buffer Overflow
CVE-2020-7374MEDIUM22 may 2020
Documalis Free PDF Editor / Free PDF Scanner Stack Based Buffer Overflow
28RIESGO
abrir
GitHub PoC
saltstack CVE-2020-11652
CVE-2020-11652MEDIUMbajo ataque22 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC
HKirito/phpmyadmin4.4_cve-2016-5734
CVE-2016-573422 may 2020
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2016-573422 may 2020
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
CVE-2020-5752localwindows22 may 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
GitHub PoC2
CVE-2017-17485:Jackson-databind RCE
CVE-2017-17485CRITICAL22 may 2020
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque22 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque22 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Exploit-DB
OpenEDX platform Ironwood 2.5 - Remote Code Execution
CVE-2020-13144webappsmultiple21 may 2020
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RIESGO
abrir
GitHub PoC13
Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALbajo ataqueransomware21 may 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
Exploit-DB
BIND - 'TSIG' Denial of Service
CVE-2020-8617HIGHdosmultiple20 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
GitHub PoC45
PoC for CVE-2020-8617 (BIND)
CVE-2020-8617HIGH20 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
anteriorpágina 769 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.